SecurityMessageProperty.cs 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324
  1. //------------------------------------------------------------
  2. // Copyright (c) Microsoft Corporation. All rights reserved.
  3. //------------------------------------------------------------
  4. namespace System.ServiceModel.Security
  5. {
  6. using System.ServiceModel;
  7. using System.ServiceModel.Channels;
  8. using System.Collections.ObjectModel;
  9. using System.Collections.Generic;
  10. using System.IdentityModel.Claims;
  11. using System.IdentityModel.Policy;
  12. using System.IdentityModel.Tokens;
  13. using System.ServiceModel.Security.Tokens;
  14. using System.Net.Security;
  15. public class SecurityMessageProperty : IMessageProperty, IDisposable
  16. {
  17. // This is the list of outgoing supporting tokens
  18. Collection<SupportingTokenSpecification> outgoingSupportingTokens;
  19. Collection<SupportingTokenSpecification> incomingSupportingTokens;
  20. SecurityTokenSpecification transportToken;
  21. SecurityTokenSpecification protectionToken;
  22. SecurityTokenSpecification initiatorToken;
  23. SecurityTokenSpecification recipientToken;
  24. ServiceSecurityContext securityContext;
  25. ReadOnlyCollection<IAuthorizationPolicy> externalAuthorizationPolicies;
  26. string senderIdPrefix = "_";
  27. bool disposed = false;
  28. public SecurityMessageProperty()
  29. {
  30. this.securityContext = ServiceSecurityContext.Anonymous;
  31. }
  32. public ServiceSecurityContext ServiceSecurityContext
  33. {
  34. get
  35. {
  36. ThrowIfDisposed();
  37. return this.securityContext;
  38. }
  39. set
  40. {
  41. ThrowIfDisposed();
  42. this.securityContext = value;
  43. }
  44. }
  45. public ReadOnlyCollection<IAuthorizationPolicy> ExternalAuthorizationPolicies
  46. {
  47. get
  48. {
  49. return this.externalAuthorizationPolicies;
  50. }
  51. set
  52. {
  53. this.externalAuthorizationPolicies = value;
  54. }
  55. }
  56. public SecurityTokenSpecification ProtectionToken
  57. {
  58. get
  59. {
  60. ThrowIfDisposed();
  61. return this.protectionToken;
  62. }
  63. set
  64. {
  65. ThrowIfDisposed();
  66. this.protectionToken = value;
  67. }
  68. }
  69. public SecurityTokenSpecification InitiatorToken
  70. {
  71. get
  72. {
  73. ThrowIfDisposed();
  74. return this.initiatorToken;
  75. }
  76. set
  77. {
  78. ThrowIfDisposed();
  79. this.initiatorToken = value;
  80. }
  81. }
  82. public SecurityTokenSpecification RecipientToken
  83. {
  84. get
  85. {
  86. ThrowIfDisposed();
  87. return this.recipientToken;
  88. }
  89. set
  90. {
  91. ThrowIfDisposed();
  92. this.recipientToken = value;
  93. }
  94. }
  95. public SecurityTokenSpecification TransportToken
  96. {
  97. get
  98. {
  99. ThrowIfDisposed();
  100. return this.transportToken;
  101. }
  102. set
  103. {
  104. ThrowIfDisposed();
  105. this.transportToken = value;
  106. }
  107. }
  108. public string SenderIdPrefix
  109. {
  110. get
  111. {
  112. return this.senderIdPrefix;
  113. }
  114. set
  115. {
  116. XmlHelper.ValidateIdPrefix(value);
  117. this.senderIdPrefix = value;
  118. }
  119. }
  120. public bool HasIncomingSupportingTokens
  121. {
  122. get
  123. {
  124. ThrowIfDisposed();
  125. return ((this.incomingSupportingTokens != null) && (this.incomingSupportingTokens.Count > 0));
  126. }
  127. }
  128. public Collection<SupportingTokenSpecification> IncomingSupportingTokens
  129. {
  130. get
  131. {
  132. ThrowIfDisposed();
  133. if (this.incomingSupportingTokens == null)
  134. {
  135. this.incomingSupportingTokens = new Collection<SupportingTokenSpecification>();
  136. }
  137. return this.incomingSupportingTokens;
  138. }
  139. }
  140. public Collection<SupportingTokenSpecification> OutgoingSupportingTokens
  141. {
  142. get
  143. {
  144. if (this.outgoingSupportingTokens == null)
  145. {
  146. this.outgoingSupportingTokens = new Collection<SupportingTokenSpecification>();
  147. }
  148. return this.outgoingSupportingTokens;
  149. }
  150. }
  151. internal bool HasOutgoingSupportingTokens
  152. {
  153. get
  154. {
  155. return ((this.outgoingSupportingTokens != null) && (this.outgoingSupportingTokens.Count > 0));
  156. }
  157. }
  158. public IMessageProperty CreateCopy()
  159. {
  160. ThrowIfDisposed();
  161. SecurityMessageProperty result = new SecurityMessageProperty();
  162. if (this.HasOutgoingSupportingTokens)
  163. {
  164. for (int i = 0; i < this.outgoingSupportingTokens.Count; ++i)
  165. {
  166. result.OutgoingSupportingTokens.Add(this.outgoingSupportingTokens[i]);
  167. }
  168. }
  169. if (this.HasIncomingSupportingTokens)
  170. {
  171. for (int i = 0; i < this.incomingSupportingTokens.Count; ++i)
  172. {
  173. result.IncomingSupportingTokens.Add(this.incomingSupportingTokens[i]);
  174. }
  175. }
  176. result.securityContext = this.securityContext;
  177. result.externalAuthorizationPolicies = this.externalAuthorizationPolicies;
  178. result.senderIdPrefix = this.senderIdPrefix;
  179. result.protectionToken = this.protectionToken;
  180. result.initiatorToken = this.initiatorToken;
  181. result.recipientToken = this.recipientToken;
  182. result.transportToken = this.transportToken;
  183. return result;
  184. }
  185. public static SecurityMessageProperty GetOrCreate(Message message)
  186. {
  187. if (message == null)
  188. throw DiagnosticUtility.ExceptionUtility.ThrowHelperArgumentNull("message");
  189. SecurityMessageProperty result = null;
  190. if (message.Properties != null)
  191. result = message.Properties.Security;
  192. if (result == null)
  193. {
  194. result = new SecurityMessageProperty();
  195. message.Properties.Security = result;
  196. }
  197. return result;
  198. }
  199. void AddAuthorizationPolicies(SecurityTokenSpecification spec, Collection<IAuthorizationPolicy> policies)
  200. {
  201. if (spec != null && spec.SecurityTokenPolicies != null && spec.SecurityTokenPolicies.Count > 0)
  202. {
  203. for (int i = 0; i < spec.SecurityTokenPolicies.Count; ++i)
  204. {
  205. policies.Add(spec.SecurityTokenPolicies[i]);
  206. }
  207. }
  208. }
  209. internal ReadOnlyCollection<IAuthorizationPolicy> GetInitiatorTokenAuthorizationPolicies()
  210. {
  211. return GetInitiatorTokenAuthorizationPolicies(true);
  212. }
  213. internal ReadOnlyCollection<IAuthorizationPolicy> GetInitiatorTokenAuthorizationPolicies(bool includeTransportToken)
  214. {
  215. return GetInitiatorTokenAuthorizationPolicies(includeTransportToken, null);
  216. }
  217. internal ReadOnlyCollection<IAuthorizationPolicy> GetInitiatorTokenAuthorizationPolicies(bool includeTransportToken, SecurityContextSecurityToken supportingSessionTokenToExclude)
  218. {
  219. // fast path
  220. if (!this.HasIncomingSupportingTokens)
  221. {
  222. if (this.transportToken != null && this.initiatorToken == null && this.protectionToken == null)
  223. {
  224. if (includeTransportToken && this.transportToken.SecurityTokenPolicies != null)
  225. {
  226. return this.transportToken.SecurityTokenPolicies;
  227. }
  228. else
  229. {
  230. return EmptyReadOnlyCollection<IAuthorizationPolicy>.Instance;
  231. }
  232. }
  233. else if (this.transportToken == null && this.initiatorToken != null && this.protectionToken == null)
  234. {
  235. return this.initiatorToken.SecurityTokenPolicies ?? EmptyReadOnlyCollection<IAuthorizationPolicy>.Instance;
  236. }
  237. else if (this.transportToken == null && this.initiatorToken == null && this.protectionToken != null)
  238. {
  239. return this.protectionToken.SecurityTokenPolicies ?? EmptyReadOnlyCollection<IAuthorizationPolicy>.Instance;
  240. }
  241. }
  242. Collection<IAuthorizationPolicy> policies = new Collection<IAuthorizationPolicy>();
  243. if (includeTransportToken)
  244. {
  245. AddAuthorizationPolicies(this.transportToken, policies);
  246. }
  247. AddAuthorizationPolicies(this.initiatorToken, policies);
  248. AddAuthorizationPolicies(this.protectionToken, policies);
  249. if (this.HasIncomingSupportingTokens)
  250. {
  251. for (int i = 0; i < this.incomingSupportingTokens.Count; ++i)
  252. {
  253. if (supportingSessionTokenToExclude != null)
  254. {
  255. SecurityContextSecurityToken sct = this.incomingSupportingTokens[i].SecurityToken as SecurityContextSecurityToken;
  256. if (sct != null && sct.ContextId == supportingSessionTokenToExclude.ContextId)
  257. {
  258. continue;
  259. }
  260. }
  261. SecurityTokenAttachmentMode attachmentMode = this.incomingSupportingTokens[i].SecurityTokenAttachmentMode;
  262. // a safety net in case more attachment modes get added to the product without
  263. // reviewing this code.
  264. if (attachmentMode == SecurityTokenAttachmentMode.Endorsing
  265. || attachmentMode == SecurityTokenAttachmentMode.Signed
  266. || attachmentMode == SecurityTokenAttachmentMode.SignedEncrypted
  267. || attachmentMode == SecurityTokenAttachmentMode.SignedEndorsing)
  268. {
  269. AddAuthorizationPolicies(this.incomingSupportingTokens[i], policies);
  270. }
  271. }
  272. }
  273. return new ReadOnlyCollection<IAuthorizationPolicy>(policies);
  274. }
  275. public void Dispose()
  276. {
  277. // do no-op for future V2
  278. if (!this.disposed)
  279. {
  280. this.disposed = true;
  281. }
  282. }
  283. void ThrowIfDisposed()
  284. {
  285. if (this.disposed)
  286. {
  287. throw DiagnosticUtility.ExceptionUtility.ThrowHelperError(new ObjectDisposedException(this.GetType().FullName));
  288. }
  289. }
  290. }
  291. }